CVE-2012-0290
Last modified
CVE-2012-0290 is a vulnerability of currently unknown severity. Symantec pcAnywhere through 12.5.3, Altiris IT Management Suite pcAnywhere Solution 7.0 (aka 12.5.x) and 7.1 (aka 12.6.x), Altiris Client Management Suite pcAnywhere Solution 7.0 (aka 12.5.x) and 7.1 (aka 12.6.x), and Altiris Deployment Solution Remote pcAnywhere Solution 7.1 (aka 12.5.x and 12.6.x) do not properly handle the client state after abnormal termination of a remote session, which allows remote attackers to obtain access to the client by leveraging an "open client session.". EPSS estimates a 2.68% chance of exploitation in the next 30 days.
Description
Symantec pcAnywhere through 12.5.3, Altiris IT Management Suite pcAnywhere Solution 7.0 (aka 12.5.x) and 7.1 (aka 12.6.x), Altiris Client Management Suite pcAnywhere Solution 7.0 (aka 12.5.x) and 7.1 (aka 12.6.x), and Altiris Deployment Solution Remote pcAnywhere Solution 7.1 (aka 12.5.x and 12.6.x) do not properly handle the client state after abnormal termination of a remote session, which allows remote attackers to obtain access to the client by leveraging an "open client session."
Metrics
Affected Software
| Vendor | Product | Versions | Update |
|---|---|---|---|
| Symantec | Pcanywhere | <= 12.5.3 | — |
| Symantec | Pcanywhere | 5.0 | — |
| Symantec | Pcanywhere | 8.0 | — |
| Symantec | Pcanywhere | 9.2 | — |
| Symantec | Pcanywhere | 10.5 | — |
| Symantec | Pcanywhere | 11.5 | — |
| Symantec | Pcanywhere | 11.5.1 | — |
| Symantec | Pcanywhere | 12.1 | — |
| Symantec | Pcanywhere | 12.5 | Sp1 |
| Symantec | Pcanywhere | 12.5.265 | — |
| Symantec | Pcanywhere | 12.5.539 | — |
| Symantec | Pcanywhere | 12.6.65 | — |
| Symantec | Pcanywhere | 12.6.7580 | — |
| Symantec | Altiris Client Management Suite Pcanywhere Solution | 12.5 | — |
| Symantec | Altiris Client Management Suite Pcanywhere Solution | 12.6 | — |
| Symantec | Altiris Deployment Solution Remote Pcanywhere Solution | 12.5 | — |
| Symantec | Altiris Deployment Solution Remote Pcanywhere Solution | 12.6 | — |
References
Timeline
- Published
- Last Modified
- Status
- Modified
Frequently Asked Questions
What is CVE-2012-0290?
How severe is CVE-2012-0290?
How do I fix CVE-2012-0290?
Are you affected by CVE-2012-0290?
Run a free Strix scan to check your systems for this vulnerability.
Scan your code nowSource: NVD / NIST
